153 Million Driver's Licenses for Sale — Plus Two Windows Zero-Days Being Exploited Now
Monday, September 14, 2026 · 5-minute read
A new identity theft service called Nexus appeared on a Russian cybercrime forum this week, selling scans of more than 153 million U.S. and Canadian driver's licenses — along with passports, medical cards, and government access badges. Security journalist Brian Krebs confirmed his own license was in the database, with a timestamp matching a trip he made in June 2025. The images appear to be coming from an ongoing breach at a major identity verification company whose customers include multiple Fortune 500 firms — and the stolen data keeps growing, with nearly 400,000 new records added in a single 24-hour window. The FBI's New Orleans field office has opened an investigation.
↗ Krebs on SecurityThe Dutch national cybersecurity agency (NCSC) is sounding the alarm over two critical bugs in Check Point VPN software, tracked as CVE-2026-85102 and CVE-2026-85103. The agency says exploitation is imminent, meaning attackers are likely already testing ways to break in. If you or your company uses Check Point VPN, patching right now is not optional.
↗ BleepingComputerFlorida's Department of Highway Safety and Motor Vehicles confirmed that its DAVID driver database was breached after attackers got in using login credentials stolen from a police department employee. This is a classic case of credential theft opening a very large door: DAVID contains driving records and personal data on millions of Florida residents. The state has not yet disclosed how many records were accessed.
↗ BleepingComputerGroups linked to the ShinyHunters and Helix extortion gangs are running a slick new scam against corporate Microsoft users. They send realistic-looking emails that mimic passkey and single sign-on prompts, tricking employees into handing over access to their Microsoft 365 accounts. Once inside, attackers steal data from email, files, and cloud storage. A separate but related campaign sent over a million fake CEO emails to accounts payable departments, trying to trick staff into wiring money for fake invoices — with the email templates written by AI. Both campaigns are actively hitting U.S. businesses right now.
A browser extension called "Twitch Enhanced Viewer | JeetBot," available on both Chrome and Firefox, has been quietly stealing OAuth tokens from nearly 31,000 users and sending them to servers run by a Russian bot service. The extension advertised itself as a tool for streamers that unlocks 1080p streams in restricted regions — a convincing pitch. Both the Chrome and Firefox versions are still live and available to download as of today. Anyone who installed this extension should assume their Twitch account is compromised.
This is one of two zero-day bugs fixed in Microsoft's record-breaking September Patch Tuesday — which patched a jaw-dropping 974 vulnerabilities in one go. This flaw lets an attacker who already has limited access to a Windows machine quietly upgrade themselves to full administrator control, with no help needed from the user. It is being actively exploited right now in the wild.
Status: Patch available — install Microsoft's September 2026 updates immediately. Note: some users are reporting that these updates are also causing Remote Desktop and USB audio issues on Windows Server, so check with your IT team before deploying to critical systems.
The second actively exploited zero-day in this month's Windows patch batch. Like its twin above, it allows an attacker to gain full administrator-level control over a vulnerable Windows system. Both bugs are being used in real attacks today — they were not discovered before attackers found them.
Status: Patch available — covered by the same September 2026 Microsoft update package.
A China-aligned espionage group is exploiting a critical flaw in Sogou Input Method, a popular Chinese-language keyboard app for Windows, to plant a backdoor called GrayRabbit. If you have Sogou installed — especially in a corporate environment — you should update or remove it right away.
Status: Actively exploited. Update Sogou Input Method to the latest version immediately.
CISA has issued a warning that attackers are now actively exploiting a maximum-severity vulnerability in GitLab, a platform widely used by software development teams to store and manage code. A flaw rated 10 out of 10 means an attacker can likely take over the system with no authentication required. Any organization running a self-hosted GitLab instance needs to act today.
Status: Actively exploited in the wild. Apply GitLab's patch immediately; if you cannot patch, take the instance offline until you can.
WordPress — which powers roughly 43% of all websites — has rolled out automated security scanning that checks every plugin update before it reaches users. Previously, plugins were reviewed when first submitted to the directory, but updates shipped with no consistent security check. That gap was exploited on July 28, 2026, when a backdoor was quietly slipped into a plugin with 20,000 active installations — and caught only because it was still within a review cooldown window. The new system uses automated analysis to flag suspicious changes before they ever reach a website owner's update queue. It won't catch everything, but it closes a real and previously invisible gap in the plugin supply chain.
Imagine walking up to a vending machine, typing in any American's name, and getting back a high-resolution scan of their driver's license — front, back, infrared, and ultraviolet — along with a timestamp of exactly when and where they showed their ID. That is essentially what a new dark web service called Nexus is offering, and it appears to have over 153 million records to sell.
The data doesn't appear to come from a single dramatic hack. Instead, researchers believe it's draining slowly and continuously from an identity verification company — the kind of business that asks you to "snap a photo of your ID" when you're renting a car, boarding a flight, or signing up for a financial service. Brian Krebs at Krebs on Security confirmed his own license was in the database, timestamped to match a flight he took in June 2025. Nine out of nine friends and family members he checked found the same pattern: their license scan matched a specific trip. The FBI has opened an investigation out of its New Orleans field office, but the breach appears to still be active — the record count grew by nearly 400,000 in a single day.
For regular people, this is significant. A driver's license isn't just proof you can drive — it's one of the most commonly used pieces of identity. With a high-resolution scan of both sides, criminals can open bank accounts, apply for loans, file fraudulent tax returns, or create fake IDs in your name. The ultraviolet and infrared scans included in some records make the documents even more useful for forgery. If you have used an identity verification service — at an airport, car rental counter, or financial app — in the past couple of years, your license may already be in this database.
Watch for signs of identity theft in the coming months: unexpected credit inquiries, unfamiliar accounts on your credit report, or mail from financial institutions you didn't contact. Consider placing a free credit freeze at all three major bureaus (Equifax, Experian, TransUnion) — it costs nothing and stops most new account fraud cold.